Virtual Private Networks (VPN) IPsec
Digi Connect IT® 16/48 User Guide
260
Format:
primary_ipsec_tunnel
backup_ipsec_tunnel
Optional: yes
Current value:
(config vpn ipsec tunnel backup_ipsec_tunnel)> ipsec_failover
b. Set the primary IPsec tunnel:
(config vpn ipsec tunnel backup_ipsec_tunnel)> ipsec_failover primary_
ipsec_tunnel
(config vpn ipsec tunnel backup_ipsec_tunnel)>
Configure SureLink active recovery for IPsec
You can configure the Connect IT 16/48 device to regularly probe IPsec client connections to
determine if the connection has failed and take remedial action.
You can also configure the IPsec tunnel to fail over to a backup tunnel. See Configure IPsec failover for
further information.
Required configuration items
n A valid IPsec configuration. See Configure an IPsec tunnel for configuration instructions.
n Enable IPsec active recovery.
n The behavior of the Connect IT 16/48 device upon IPsec failure: either
l Restart the IPsec interface
l Reboot the device.
Additional configuration items
n The interval between connectivity tests.
n Whether the interface should be considered to have failed if one of the test targets fails, or all
of the test targets fail.
n The number of probe attempts before the IPsec connection is considered to have failed.
n The amount of time that the device should wait for a response to a probe attempt before
considering it to have failed.
To configure the Connect IT 16/48 device to regularly probe the IPsec connection:
WebUI
1. Log into the Connect IT 16/48 WebUI as a user with full Admin access rights.
2. On the menu, click System. Under Configuration, click Device Configuration.